1. Who is responsible for your data
The controller of the personal data described in this policy is the operator of Vizo: אבו אלשיך חסן, registered in Israel as an exempt dealer (עוסק פטור) under the Israeli Value Added Tax Law, business number 215157843. Registered business address: אבן ח'לדון 75, רהט 8535700, Israel. For anything about your data — access, correction, deletion or a question — write to support@askvizo.com.
2. The short version
Before AI use, Vizo asks permission to share your questions, relevant study files and selected images, audio or shared screen content with OpenAI and Google. You can decline and continue reading saved material and writing personal notes. Revoke permission in Settings → Vizo AI to prevent new AI requests; end an active voice lesson first.
- Vizo does not store live video. Selected camera and screen frames are sent to AI providers for interpretation. Provider processing and security retention are governed by their API terms.
- Vizo does not keep live voice recordings. Voice is streamed to the AI provider. Transcripts and saved lesson content may remain in your session history.
- What we do keep is the material you deliberately upload, the text extracted from it, and the boards your sessions produce — because those are the things you asked us to remember.
- We do not sell your data and we do not use it to train third-party foundation models.
3. What we collect
Account data
Your email address and authentication identifiers, held so you can sign in. If you sign in with a third-party provider, we receive the basic profile they release to us.
Study profile
Your academic level and optional field of study. This is used for one purpose: pitching explanations at the right level.
Course material you upload
PDFs of syllabi, notes and slides. We extract their text, split it into passages and compute vector embeddings so the tutor can cite your own materials rather than a generic textbook. The original file is stored in your private bucket.
Session output
The blackboard content a session produces, the tutor’s interventions, and timestamps. This is what makes a module still remember last week’s lesson.
Conversations and notes
The text of your conversations with the tutor and the typed text of your notes are saved with your sessions and notebooks, so you can reopen them. Handwriting is stored as the strokes you drew; it is only read as text when you ask Vizo to look at it.
The search index over your own study record
So that Vizo can find your own earlier work when you ask for it — “how did you explain eigenvalues last week?”, “find my note on Green’s theorem” — it keeps a private search index over the text of your saved tutor sessions, your typed notes, your processed lectures and the study sheets it generated for you. The index holds short passages of that text, their embeddings (computed by OpenAI) and a pointer to the original. It is derived data: it is refreshed when the original changes, and removed when the original is deleted or moved to the Trash, when you delete a course, or when you delete your account. It is read only to answer your own requests, under the same row-level security as the originals.
Personal Course Books
When you ask for a Personal Course Book, Vizo summarises your course’s documents, lectures, notes and sessions with an AI provider, keeps those summaries so an unchanged source is never summarised twice, and saves the finished PDF in your Library. A summary is deleted when the source it came from is deleted or changes.
Personalisation (optional)
Only if you turn on Personalise Vizo (Settings → Vizo AI), Vizo keeps a small learner profile: preferences you enter, and a few facts inferred from your sessions and practice — for example a mistake you make more than once. You can review or delete each fact there, or turn the feature off; while it is off, no inferred facts are added or used. Searching your own saved work is not personalisation: it works either way, because it is your material, used only when you ask for it.
Live camera, screen and microphone
On iOS, screen sharing passes the latest reduced-size frame through a temporary file shared with Vizo’s broadcast extension. It is replaced as new frames arrive and removed when sharing stops or the app next starts after an interruption.
Only while a session is running, and only with the permission your browser asks you for. Frames and audio are transmitted for real-time interpretation and are not written to our storage. You can stop sharing at any time from the session controls or your browser.
Technical and usage data
Basic operational logs and error reports needed to keep the service running and secure, plus the Energy balance used to meter your usage.
4. Why we may process it
- To perform our contract with you — running sessions, storing your courses, remembering your boards, billing your subscription.
- Legitimate interests — keeping the service secure, preventing abuse, diagnosing faults, and understanding aggregate usage to improve the product.
- Consent — camera, screen and microphone access, which your browser requests explicitly and you can withdraw at any time.
- Legal obligation — tax and accounting records relating to purchases.
5. Who we share it with
We use a small number of processors, each for a defined purpose:
- Supabase — database, authentication and file storage. Your rows are isolated by row-level security.
- OpenAI — real-time speech, vision and language understanding, and text embeddings. Content is sent to be processed and returned; under OpenAI’s API terms it is not used to train their models.
- Lemon Squeezy — our Merchant of Record. They handle checkout, payment details and tax. We never see or store your card details.
- Google — AI responses when a Google model is used, and authentication if you choose Google sign-in. Study content is sent to the configured AI API for the requested task.
- Apple and RevenueCat — Apple authentication and iOS purchase verification. RevenueCat receives your Vizo account identifier, product and transaction information. Apple credentials needed for access revocation are encrypted on the server; native Vizo sessions are kept in the device Keychain.
- Our hosting provider — serving the application.
We may also disclose information where legally required, or to protect the rights and safety of our users. We do not sell personal data and we do not share it with advertisers.
6. International transfers
Our providers may process data outside your country, including in the United States. Where that happens we rely on the safeguards those providers offer, such as Standard Contractual Clauses.
7. How long we keep it
- Live camera, screen and audio — Vizo does not keep recordings. AI providers may retain submitted content under their service and security policies. Saved transcripts and lesson notes are retained with the session.
- Account, courses, uploads and saved boards — until you delete them or close your account.
- Search index and summaries of your own material — for as long as the material they were derived from; they are removed with it.
- Deleted content — removed from active systems; backup copies remain subject to our storage provider’s backup retention. Contact us for the applicable retention period.
- Billing records — retained as long as tax law requires, typically 6–7 years, by our Merchant of Record.
8. Your rights
Delete your account in Settings → Account. This removes the account and stored study content and requests Apple credential revocation where available. Subscription cancellation is managed separately with the payment provider. A restricted hashed email record may be retained to prevent repeated trial abuse; it is pseudonymous, not anonymous. Your manual notes and unfinished writing may also have account-scoped recovery copies on your device.
Depending on where you live, you may have the right to access, correct, export, delete or restrict processing of your personal data, and to object to processing based on legitimate interests. You can delete individual courses, modules and uploads from inside the app at any time.
To exercise any right, email support@askvizo.com. We will respond within 30 days. If you are in the EEA or UK you also have the right to complain to your local data protection authority.
9. Children
Vizo is not directed at children under 16. We do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.
10. Security
Data is encrypted in transit and at rest. Access to your rows is enforced at the database level by row-level security policies, not merely by application code. Billing entitlements can only be changed by our payment webhook — never by a browser client. No system is perfectly secure, but we design on the assumption that any given layer may fail.
11. Cookies
We use strictly necessary cookies to keep you signed in and to maintain your session. We do not use advertising or cross-site tracking cookies.
12. Changes and contact
We will post any changes here and, where the change is material, notify you in the app or by email. Contact: support@askvizo.com.